Penetration Testing Information Collection Method, Device, Equipment, Medium and Program Product
By automatically collecting and processing information in penetration testing, the problem of low artificial intelligence in the existing technology is solved, and more efficient and accurate penetration testing is achieved.
Patent Information
- Application Number
- CN202111353694.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-16
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2041-11-16
AI Technical Summary
In existing penetration tests, the method of manually collecting and processing information is not very intelligent and inefficient.
Provide a method for collecting penetration testing information, by collecting target information from the target server, obtaining the database connection password of the database project and database connection tool, decrypting the ciphertext password, and generating a penetration network topology map. The method includes collecting modules, obtaining modules, decrypting modules and generating modules to realize automated information collection and processing.
It improves the intelligence of the collection and processing of target server information, reduces manual intervention, and improves the efficiency and accuracy of penetration testing.
Smart Images

Figure CN113987520B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information security technology, and in particular, to a method, device, equipment, medium, and program product for collecting penetration testing information. Background Art
[0002] With the development of computer technology, computer information security technology has gradually become the focus of research in recent years. In particular, penetration testing, as one of the computer information security technologies, has become the top priority of research in recent years. Among them, penetration testing is a technology for discovering security vulnerabilities in computer systems, which is mainly divided into multiple stages such as pre-interaction, information collection, penetration attack, and report generation. The information collection stage is the basis for the penetration attack stage. In addition, in order to ensure the accuracy of the penetration attack, it is also necessary to process the information collected in the information collection stage.
[0003] In the prior art, in the case of performing a penetration test on a computer system, it is usually manual to collect information in the computer system and manually process the collected information.
[0004] However, the method of collecting and processing information manually has low intelligence. Summary of the Invention
[0005] Based on this, it is necessary to provide a method, device, equipment, medium, and program product for collecting penetration testing information in view of the above technical problems.
[0006] In a first aspect, this application provides a method for collecting penetration testing information. The method includes: collecting target information from a target server; obtaining the database connection password of a database project and the database connection password of a database connection tool in the target server based on the target information, where the database connection password includes a plaintext password and a ciphertext password; obtaining decryption information based on the target information, and decrypting the ciphertext password based on the decryption information to obtain a decrypted password; generating a penetration network topology diagram based on the decrypted password, the plaintext password, and the target information.
[0007] In one embodiment, obtaining the database connection password of a database project and the database connection password of a database connection tool in the target server based on the target information includes: obtaining first configuration file information of the database project and second configuration file information of the database connection tool based on the target information; obtaining the path of the project folder where the database project is deployed based on the first configuration file information, and traversing the project folder based on the path to obtain the database password configuration file of the database project from the project folder, and reading the database connection password of the database project from the database password configuration file; reading the database connection password of the database connection tool from the second configuration file information.
[0008] In one embodiment, the target information includes registry information and service list information. Before obtaining the first configuration file information of the database project and the second configuration file information of the database connection tool based on the target information, the method further includes: generating a software list of the software installed in the target server based on the registry information and the service list information; determining the database project and the database connection tool in the target server according to the software list.
[0009] In one embodiment, the ciphertext password includes a first ciphertext password, and the first ciphertext password is the encrypted database connection password of the database project. Obtaining decryption information based on the target information includes: determining the encryption method of the first ciphertext password; obtaining the decryption information based on the target information according to the encryption method.
[0010] In one embodiment, obtaining the decryption information based on the target information according to the encryption method includes: if the encryption method is the windows DPAPI encryption method, obtaining the system user password and the system master key based on the target information, and using the obtained system user password and system master key as the decryption information; if the encryption method is the local encryption method, obtaining the encrypted code file of the database project and the first encryption key corresponding to the encrypted code file based on the target information, and using the obtained encrypted code file and the first encryption key as the decryption information.
[0011] In one embodiment, obtaining the system user password and the system master key based on the target information includes: obtaining the system user password from the target information; obtaining the system master key from the target server based on the system user password.
[0012] In one embodiment, the target information includes the first configuration file information of the database project. Obtaining the encrypted code file of the database project and the first encryption key corresponding to the encrypted code file based on the target information includes: obtaining the path of the project folder where the database project is deployed based on the first configuration file information; traversing the project folder based on the path to obtain the encrypted code file and the first encryption key from the project folder.
[0013] In one embodiment, the ciphertext password includes a second ciphertext password, and the second ciphertext password is the encrypted database connection password of the database connection tool. Obtaining decryption information based on the target information includes: reading the encryption algorithm used by the database connection tool and the second encryption key corresponding to the encryption algorithm from the target information, and using the encryption algorithm and the second encryption key as the decryption information.
[0014] In one embodiment, target information is collected from a target server, including: collecting the target information from the target server based on the obtained command execution permission for the target server; wherein, the command execution permission is obtained after a penetration attack on the target server.
[0015] In a second aspect, the present application further provides a penetration testing information collection device. The device includes: a collection module for collecting target information from a target server; a first acquisition module for obtaining the database connection password of a database project and the database connection password of a database connection tool in the target server based on the target information, wherein the database connection password includes a plaintext password and a ciphertext password; a decryption module for obtaining decryption information based on the target information and decrypting the ciphertext password based on the decryption information to obtain a decrypted password; and a generation module for generating a penetration network topology diagram based on the decrypted password, the plaintext password, and the target information.
[0016] In one embodiment, the acquisition module is specifically configured to: obtain first configuration file information of the database project and second configuration file information of the database connection tool based on the target information; obtain the path of the project folder where the database project is deployed based on the first configuration file information, and traverse the project folder based on the path to obtain the database password configuration file of the database project from the project folder, and read the database connection password of the database project from the database password configuration file; and read the database connection password of the database connection tool from the second configuration file information.
[0017] In one embodiment, the target information includes registry information and service list information, and the device further includes: a second acquisition module for obtaining a software list of software installed in the target server based on the registry information and the service list information; and a determination module for determining the database project and the database connection tool in the target server according to the software list.
[0018] In one embodiment, the ciphertext password includes a first ciphertext password, which is the encrypted database connection password of the database project. The decryption module is specifically configured to: determine the encryption method of the first ciphertext password; and obtain the decryption information based on the target information according to the encryption method.
[0019] In one embodiment, the decryption module is specifically configured to: if the encryption method is the windows DPAPI encryption method, obtain the system user password and the system master key based on the target information, and use the obtained system user password and system master key as the decryption information; if the encryption method is the local encryption method, obtain the encrypted code file of the database project and the first encryption key corresponding to the encrypted code file based on the target information, and use the obtained encrypted code file and the first encryption key as the decryption information.
[0020] In one embodiment, the decryption module is specifically configured to: obtain the system user password from the target information; obtain the system master key from the target server based on the system user password.
[0021] In one embodiment, the target information includes the first configuration file information of the database project. The decryption module is specifically configured to: obtain the path of the project folder where the database project is deployed based on the first configuration file information; traverse the project folder based on the path to obtain the encrypted code file and the first encryption key from the project folder.
[0022] In one embodiment, the ciphertext password includes a second ciphertext password, which is the database connection password of the encrypted database connection tool. The decryption module is specifically configured to: read the encryption algorithm used by the database connection tool and the second encryption key corresponding to the encryption algorithm from the target information, and use the encryption algorithm and the second encryption key as the decryption information.
[0023] In one embodiment, the collection module is specifically configured to: collect the target information from the target server based on the obtained command execution permission of the target server; wherein, the command execution permission is obtained after a penetration attack on the target server.
[0024] In a third aspect, the present application further provides a computer device, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the steps of the method described in any item of the first aspect above are implemented.
[0025] In a fourth aspect, the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the method described in any item of the first aspect above are implemented.
[0026] In a fifth aspect, the present application further provides a computer program product. The computer program product includes a computer program, and when the computer program is executed by a processor, the steps of the method described in any item of the first aspect above are implemented.
[0027] The beneficial effects brought by the technical solution provided in the embodiments of the present application at least include:
[0028] In the embodiments of the present application, based on the target information collected from the target server, the database connection password of the database item in the target server and the database connection password of the database connection tool are obtained. At the same time, decryption information is obtained based on the target information, and the encrypted password in the database connection password is decrypted based on the decryption information to obtain the decrypted password. Finally, a penetration network topology map is generated based on the decrypted password, the plaintext password, and the target information. Because the collection of target information, the acquisition of database connection passwords, and the decryption information are all automated, and the information processing process of decrypting the encrypted password is also automated and does not require manual participation. Therefore, the intelligence of collecting information from the target server and processing this information is improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0029] Figure 1 It is a schematic diagram of an implementation environment provided by the embodiments of the present application;
[0030] Figure 2 It is a flowchart of a penetration test information collection method provided by the embodiments of the present application;
[0031] Figure 3 It is a flowchart of a technical process for obtaining a database connection password provided by the embodiments of the present application;
[0032] Figure 4 It is a flowchart of a technical process for obtaining decryption information corresponding to the first encrypted password provided by the embodiments of the present application;
[0033] Figure 5 It is a flowchart of another penetration test information collection method provided by the embodiments of the present application;
[0034] Figure 6 It is a block diagram of a penetration test information collection device provided by the embodiments of the present application;
[0035] Figure 7 It is a block diagram of another penetration test information collection device provided by the embodiments of the present application;
[0036] Figure 8 It is an internal structure diagram of a computer device provided by the embodiments of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0037] In order to make the objectives, technical solutions, and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0038] With the development of computer technology, computer information security technology has gradually become the focus of research in recent years. In particular, penetration testing, as one of the computer information security technologies, has been the top priority of research in recent years. Among them, penetration testing is a technology for detecting security vulnerabilities in computer systems, which is mainly divided into multiple stages such as pre-interaction, information collection, penetration attack, and report generation. The information collection stage is the basis for the penetration attack stage. In addition, in order to ensure the accuracy of the penetration attack, it is also necessary to process the information collected in the information collection stage. In the prior art, in the case of performing a penetration test on a computer system, information in the computer system is usually collected manually and the collected information is processed manually. However, the method of collecting and processing information manually has low intelligence.
[0039] In view of this, the embodiments of the present application provide a penetration testing information collection method, device, equipment, medium, and program product. Using this penetration testing information collection can improve the intelligence of collecting information in the target server and processing the information.
[0040] Please refer to Figure 1 , which shows a schematic diagram of the implementation environment involved in the penetration testing information collection method provided by the embodiments of the present application. As Figure 1 shown, the implementation environment may include a unified scheduling server 101 and a target server 102. Among them, the unified scheduling server 101 can communicate with the target server 102. The target server 102 is the server to be penetrated and tested. The unified scheduling server 101 is used to obtain the target information in the target server 102 and process the target information. It should be noted that the unified scheduling server 101 can be a single server or a server cluster composed of multiple servers; similarly, the target server 102 can be a single server or a server cluster composed of multiple servers; different servers can communicate through wired or wireless methods, and the wireless method can be implemented through WIFI, operator network, NFC (Near Field Communication), or other technologies.
[0041] Please refer to Figure 2 , which shows a flowchart of a penetration testing information collection method provided by the embodiments of the present application. This penetration testing information collection method can be applied to the Figure 1 shown unified scheduling server. As Figure 2 shown, this penetration testing information collection method may include the following steps:
[0042] Step 201, the unified scheduling server collects target information from the target server.
[0043] Among them, the target information may include the system information of the target server and the database information in the target server. The system information of the target server includes information such as registry information, service list information, system user passwords, and system master key files. The database information includes information such as database items, database connection tools, and the versions of database items and database connection tools. Optionally, the system information of the target server may further include information such as system type, system version, system patch installation directory, system environment variables, and system network connection status.
[0044] In an alternative embodiment of the present application, an alternative way for the unified scheduling server to collect target information from the target server is: the unified scheduling server collects target information from the target server based on the obtained command execution permission of the target server, where the command execution permission is obtained after a penetration attack on the target server. Optionally, a penetration testing system may be used to perform a penetration attack on the target server, where the penetration testing system is a software module that can be configured in the unified scheduling server or in the target server. Optionally, after performing a penetration attack on the target server through the penetration testing system, the command execution permission of the target server can be obtained. Among them, the command execution permission is the permission for the unified scheduling server to obtain target information from the target server. If the unified scheduling server does not obtain this command execution permission, then the unified scheduling server cannot obtain target information from the target server.
[0045] Step 202: The unified scheduling server obtains the database connection password of the database item and the database connection password of the database connection tool in the target server based on the target information.
[0046] Among them, the database connection password includes a plaintext password and a ciphertext password. The plaintext password is clear text characters that are not hidden and can be directly displayed, and the ciphertext password is the hidden characters. In the embodiment of the present application, database items and database connection tools are set in the target server. Based on the obtained target information, the database connection password of the database item and the database connection password of the database connection tool in the target server can be obtained.
[0047] Step 203: The unified scheduling server obtains decryption information based on the target information, and decrypts the ciphertext password based on the decryption information to obtain the decrypted password.
[0048] Among them, the decryption information includes information related to decryption such as the encryption method, the system master key, the system master key, and the encrypted code file. The decryption password is the password obtained after decrypting the ciphertext password. Based on the obtained decryption information, the ciphertext password can be decrypted to obtain the decryption password. In the prior art, in the face of the ciphertext password, the ciphertext password is usually decrypted manually. In the embodiment of the present application, the unified scheduling server automatically decodes the ciphertext password, which improves the intelligence of decrypting the ciphertext password and also improves the decryption efficiency. Optionally, the ciphertext password can be decrypted in an offline manner.
[0049] Step 204: The unified scheduling server generates a penetration network topology diagram based on the decryption password, the plaintext password, and the target information.
[0050] Since penetration testing mainly includes multiple stages such as pre - interaction, information collection, penetration attack, and report generation, and the information collection stage is the basis for the penetration attack stage. Therefore, after decrypting the ciphertext password in the database connection password, the unified scheduling server can penetrate the database information corresponding to the ciphertext password during the penetration attack stage, making the penetration attack on the target server more comprehensive. Based on the obtained decryption password, plaintext password, and target information, a penetration test report and a penetration network topology diagram can be generated. The penetration test report and the penetration network topology diagram provide a sufficient data basis for the subsequent penetration attack stage and can make the penetration test visual. In addition, the tester can use a database connection tool to verify the correctness of the decryption password.
[0051] In the embodiment of the present application, based on the target information collected from the target server, the database connection password of the database project in the target server and the database connection password of the database connection tool are obtained. At the same time, the decryption information is obtained based on the target information, and the ciphertext password in the database connection password is decrypted based on the decryption information to obtain the decryption password. Finally, a penetration network topology diagram is generated based on the decryption password, the plaintext password, and the target information. Because the collection of target information, the acquisition of the database connection password and the decryption information are all automated, and the process of decrypting the ciphertext password, which is an information - processing process, is also automated without the need for manual participation. Therefore, the intelligence of collecting information from the target server and processing this information is improved.
[0052] Please refer to Figure 3 , which shows a technical process for obtaining the database connection password provided by the embodiment of the present application. The embodiment of the present application further obtains the database connection password based on the obtained target information. As Figure 3 shown, the technical process may include the following steps:
[0053] Step 301: The unified scheduling server obtains the first configuration file information of the database project and the second configuration file information of the database connection tool based on the target information.
[0054] Optionally, the first configuration file information and the second configuration file information can be obtained based on the target information. Among them, the first configuration file information is the configuration file information of the database project, and the second configuration file information is the configuration file information of the database connection tool. It should be noted that before obtaining the first configuration file information and the second configuration file information, the database project and the database connection tool need to be obtained. Optionally, the steps to obtain the database project and the database connection tool can be as follows:
[0055] First, based on the registry information and the service list information, obtain the software list of the software installed in the target server. Second, determine the database project and the database connection tool in the target server according to the software list. Optionally, based on obtaining the database project and the database connection tool, the first configuration file information and the second configuration file information can be obtained, and it can be identified from the software list whether databases such as mysql, sqlsever, Navicat, SSMS, tomcat, and spring are installed.
[0056] Step 302: The unified scheduling server obtains the path of the project folder where the database project is deployed based on the first configuration file information, and traverses the project folder based on the path to obtain the database password configuration file of the database project from the project folder, and reads the database connection password of the database project from the database password configuration file.
[0057] Optionally, for the projects deployed on the target server, the database connection password of the database project is usually saved in the database password configuration file with suffixes such as properties in the project directory, and the database connection password of the database project can be obtained directly by reading this database password configuration file. At the same time, the retrieval method of traversing the project folder can prevent missing important penetration clues and ensure the sufficiency of information collection.
[0058] Step 303: The unified scheduling server reads the database connection password of the database connection tool from the second configuration file information.
[0059] The unified scheduling server can read the database connection password of the database connection tool from the obtained second configuration file information of the database connection tool. In the embodiment of the present application, the database connection password can be automatically obtained by the unified scheduling server, which improves the intelligence of obtaining the database connection password.
[0060] It should be noted that the ciphertext passwords in the above text include the first ciphertext password and the second ciphertext password. Among them, the first ciphertext password is the database connection password of the encrypted database project, and the second ciphertext password is the database connection password of the encrypted database connection tool. It is necessary to decrypt the first ciphertext password and the second ciphertext password. Thus, the decryption information includes the decryption information corresponding to the first ciphertext password and the decryption information corresponding to the second ciphertext password. Please refer to Figure 4 , which shows a technical process for obtaining the decryption information corresponding to the first ciphertext password provided by an embodiment of the present application. As Figure 4 shown, the technical process for obtaining the decryption information corresponding to the first ciphertext password may include the following steps:
[0061] Step 401: The unified scheduling server determines the encryption method of the first ciphertext password.
[0062] Optionally, the encryption method may be the windows DPAPI encryption method and the local encryption method. Among them, DPAPI is an interface for Windows system to encrypt and decrypt data. There is no need to implement the encryption and decryption code by oneself. The Microsoft system has provided verified high-quality encryption and decryption algorithms and provides a high level of security guarantee.
[0063] Step 402: The unified scheduling server obtains the decryption information based on the encryption method and the target information.
[0064] In an alternative embodiment of the present application, if the encryption methods are different, the methods for obtaining the decryption information based on the target information are also different. Optionally, if the encryption method is the windows DPAPI encryption method, the system user password and the system master key are obtained based on the target information, and the obtained system user password and system master key are used as the decryption information, where the decryption information is the decryption information corresponding to the first ciphertext password. Optionally, the system user password and the system master key can be obtained from the target information, or when it is determined that the encryption method is windows DPAPI, the system user password can be obtained from the target information first, and then the system master key can be obtained from the target server based on the system user password. Optionally, the method for obtaining the system master key from the target server based on the system user password may be: First, the system user password and the system master key file are obtained from the target information; then, the system master key file is decrypted by the system user password to obtain the system master key. After obtaining the system master key, the windows DPAPI is called to decrypt the first ciphertext password using the system master key to obtain the decryption password, where the decryption password is the decryption password corresponding to the first ciphertext password. Optionally, the system master key file and the system user password can be obtained under %APPDATA% / Microsoft / Protect / %SID%.
[0065] Optionally, if the encryption method is the local encryption method, obtain the encrypted code file of the database project and the first encryption key corresponding to the encrypted code file based on the target information, and use the obtained encrypted code file and the first encryption key as the decryption information.
[0066] Among them, the target information includes the first configuration file information of the database project. Optionally, the process of obtaining the encrypted code file of the database project and the first encryption key corresponding to the encrypted code file based on the target information may include: First, obtain the path of the project folder where the database project is deployed based on the first configuration file information; Second, based on the path, traverse the project folder to obtain the encrypted code file and the first encryption key from the project folder. Optionally, in the case of traversing the project folder, the encrypted code file and the first encryption key can be obtained through methods such as project call methods and regular matching. In an alternative embodiment of the present application, through the retrieval method of traversing the project folder, important penetration clues can be prevented from being missed, ensuring the sufficiency of information collection.
[0067] In an alternative embodiment of the present application, to obtain the decryption information corresponding to the second ciphertext password based on the target information, the optional method is: read the encryption algorithm used by the database connection tool and the second encryption key corresponding to the encryption algorithm from the target information, and use the encryption algorithm and the second encryption key as the decryption information. For example, for the Navicat database connection tool, the encrypted database connection password is saved under the second configuration file \HKEY_CURRENT_USER\SOFTWARE\PremiumSoft\Navicat\Servers\Pwd, and the encryption algorithm and the second encryption key used for the database connection password of the Navicat database connection tool are fixed.
[0068] Please refer to Figure 5 , which shows a flowchart of another penetration testing information collection method provided by an embodiment of the present application. This penetration testing information collection method can be applied to Figure 1 the unified scheduling server shown.
[0069] As Figure 5 shown, this penetration testing information collection method may include the following steps:
[0070] Step 501, the unified scheduling server obtains the command execution permission of the target server, where the command execution permission is obtained after a penetration attack on the target server.
[0071] Step 502, the unified scheduling server collects target information from the target server based on the obtained command execution permission of the target server.
[0072] Step 503: The unified scheduling server obtains the first configuration file information of the database project and the second configuration file information of the database connection tool based on the target information.
[0073] Step 504: The unified scheduling server obtains the path of the project folder where the database project is deployed based on the first configuration file information, and traverses the project folder based on the path to obtain the database password configuration file of the database project from the project folder, and reads the database connection password of the database project from the database password configuration file.
[0074] Step 505: The unified scheduling server reads the database connection password of the database connection tool from the second configuration file information.
[0075] Among them, the database connection passwords in Step 504 and Step 505 include plaintext passwords and ciphertext passwords. The ciphertext passwords include the first ciphertext password and the second ciphertext password. The first ciphertext password is the encrypted database connection password of the database project, and the second ciphertext password is the encrypted database connection password of the database connection tool.
[0076] Step 506: The unified scheduling server determines the encryption method of the first ciphertext password in the unified scheduling server.
[0077] Step 507: The unified scheduling server obtains the decryption information corresponding to the first ciphertext password based on the encryption method and the target information.
[0078] Step 508: The unified scheduling server obtains the encryption algorithm corresponding to the second ciphertext password and the second encryption key corresponding to the encryption algorithm from the target information, and uses the encryption algorithm and the second encryption key as the decryption information corresponding to the second ciphertext password.
[0079] Step 509: The unified scheduling server decrypts the first ciphertext password and the second ciphertext password respectively based on the decryption information corresponding to the first ciphertext password and the decryption information corresponding to the second ciphertext password, and obtains the decryption password corresponding to the first ciphertext password and the decryption password corresponding to the second ciphertext password respectively.
[0080] Step 510: The unified scheduling server generates a penetration network topology diagram based on the decryption password, the plaintext password, and the target information.
[0081] In the embodiments of the present application, the unified scheduling server can automatically obtain the database connection password and decryption information, and automatically decrypt the ciphertext password in the database connection password through the obtained decryption information to obtain the decrypted password, providing a sufficient data basis for the penetration attack stage, increasing the depth and breadth of penetration testing, and expanding the attack surface of penetration testing. At the same time, the penetration work can be completed quickly and silently to the greatest extent, preventing the target server from freezing and shutting down due to long-term operations or being discovered by the operation and maintenance personnel.
[0082] It should be understood that although the steps in the flowcharts involved in the above-described embodiments are sequentially shown according to the indications of the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear indication in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-described embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same moment, but can be executed at different moments. The execution order of these steps or stages is not necessarily sequential, but can be executed alternately or alternately with at least a part of other steps or steps or stages in other steps.
[0083] Please refer to Figure 6 , which shows a block diagram of a penetration testing information collection device 600 provided by an embodiment of the present application. The penetration testing information collection device can be configured in the above-mentioned unified scheduling server. As Figure 6 shown, the penetration testing information collection device 600 includes a collection module 601, a first acquisition module 602, a decryption module 603, and a generation module 604.
[0084] Among them, the collection module 601 is used to collect target information from the target server; the first acquisition module 602 is used to obtain the database connection password of the database item in the target server and the database connection password of the database connection tool based on the target information, where the database connection password includes a plaintext password and a ciphertext password; the decryption module 603 is used to obtain decryption information based on the target information and decrypt the ciphertext password based on the decryption information to obtain the decrypted password; the generation module 604 is used to generate a penetration network topology diagram based on the decrypted password, the plaintext password, and the target information.
[0085] In an alternative embodiment of the present application, the first acquisition module 602 is specifically configured to: acquire first configuration file information of the database project and second configuration file information of the database connection tool based on the target information; acquire the path of the project folder where the database project is deployed based on the first configuration file information, and traverse the project folder based on the path to acquire the database password configuration file of the database project from the project folder, and read the database connection password of the database project from the database password configuration file; read the database connection password of the database connection tool from the second configuration file information.
[0086] In an alternative embodiment of the present application, the ciphertext password includes a first ciphertext password, and the first ciphertext password is the encrypted database connection password of the database project. The decryption module 603 is specifically configured to: determine the encryption method of the first ciphertext password; acquire decryption information based on the encryption method and the target information.
[0087] In an alternative embodiment of the present application, the decryption module 603 is specifically configured to: if the encryption method is the windowsDPAPI encryption method, acquire the system user password and the system master key based on the target information, and use the acquired system user password and system master key as the decryption information; if the encryption method is the local encryption method, acquire the encrypted code file of the database project and the first encryption key corresponding to the encrypted code file based on the target information, and use the acquired encrypted code file and the first encryption key as the decryption information.
[0088] In an alternative embodiment of the present application, the decryption module 603 is specifically configured to: acquire the system user password from the target information; acquire the system master key from the target server based on the system user password.
[0089] In an alternative embodiment of the present application, the target information includes the first configuration file information of the database project. The decryption module 603 is specifically configured to: acquire the path of the project folder where the database project is deployed based on the first configuration file information; traverse the project folder based on the path to acquire the encrypted code file and the first encryption key from the project folder.
[0090] In an alternative embodiment of the present application, the ciphertext password includes a second ciphertext password, and the second ciphertext password is the encrypted database connection password of the database connection tool. The decryption module 603 is specifically configured to: read the encryption algorithm used by the database connection tool and the second encryption key corresponding to the encryption algorithm from the target information, and use the encryption algorithm and the second encryption key as the decryption information.
[0091] In an alternative embodiment of the present application, the collection module 601 is specifically configured to collect target information from the target server based on the obtained command execution permission of the target server, where the command execution permission is obtained after a penetration attack on the target server.
[0092] Please refer to Figure 7 , which shows a block diagram of another penetration testing information collection device 700 provided by an embodiment of the present application. In addition to including the modules of the penetration testing information collection device 600, the penetration testing information collection device 700 further includes a second acquisition module 605 and a determination module 606.
[0093] Among them, the second acquisition module 605 is configured to obtain a software list of the software installed in the target server based on the registry information and the service list information, where the target information includes the registry information and the service list information; the determination module 606 is configured to determine the database items and the database connection tools in the target server according to the software list.
[0094] The embodiment of the present application provides a server resource protection device, which can implement the above method embodiment, and its implementation principle and technical effect are similar, and will not be described in detail here.
[0095] Each module in the above server resource protection device can be implemented in whole or in part by software, hardware and their combination. The above modules can be embedded in or independent of the processor in the computer device in the form of hardware, or stored in the memory of the computer device in the form of software, so that the processor can call and execute the operations corresponding to the above modules.
[0096] In an embodiment, a computer device is provided. The computer device can be a unified scheduling server, and its internal structure diagram can be as Figure 8 shown. The computer device includes a processor, a memory and a network interface connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of the computer device is used to communicate with an external target server through a network connection. When the computer program is executed by the processor, it implements a penetration testing information collection method.
[0097] Those skilled in the art can understand, Figure 8The structure shown is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.
[0098] In an embodiment of the present application, a computer device is provided, including a memory and a processor. A computer program is stored in the memory. When the processor executes the computer program, the following steps are implemented: collecting target information from a target server; obtaining the database connection password of the database item in the target server and the database connection password of the database connection tool based on the target information, where the database connection password includes a plaintext password and a ciphertext password; obtaining decryption information based on the target information, and decrypting the ciphertext password based on the decryption information to obtain a decrypted password; generating a penetration network topology diagram based on the decrypted password, the plaintext password, and the target information.
[0099] In an embodiment of the present application, when the processor executes the computer program, the following steps are further implemented: obtaining the first configuration file information of the database item and the second configuration file information of the database connection tool based on the target information; obtaining the path of the project folder where the database item is deployed based on the first configuration file information, and traversing the project folder based on the path to obtain the database password configuration file of the database item from the project folder, and reading the database connection password of the database item from the database password configuration file; reading the database connection password of the database connection tool from the second configuration file information.
[0100] In an embodiment of the present application, the target information includes registry information and service list information. When the processor executes the computer program, the following steps are further implemented: obtaining a software list of the software installed in the target server based on the registry information and the service list information; determining the database item and the database connection tool in the target server according to the software list.
[0101] In an embodiment of the present application, the ciphertext password includes a first ciphertext password, and the first ciphertext password is the encrypted database connection password of the database item. When the processor executes the computer program, the following steps are further implemented: determining the encryption method of the first ciphertext password; obtaining decryption information based on the target information according to the encryption method.
[0102] In one embodiment of the present application, when the processor executes the computer program, the following steps are further implemented: If the encryption method is the windowsDPAPI encryption method, obtain the system user password and the system master key based on the target information, and use the obtained system user password and system master key as the decryption information; If the encryption method is the local encryption method, obtain the encrypted code file of the database project and the first encryption key corresponding to the encrypted code file based on the target information, and use the obtained encrypted code file and the first encryption key as the decryption information.
[0103] In one embodiment of the present application, when the processor executes the computer program, the following steps are further implemented: Obtain the system user password from the target information; Obtain the system master key from the target server based on the system user password.
[0104] In one embodiment of the present application, the target information includes the first configuration file information of the database project. When the processor executes the computer program, the following steps are further implemented: Obtain the path of the project folder where the database project is deployed based on the first configuration file information; Based on the path, traverse the project folder to obtain the encrypted code file and the first encryption key from the project folder.
[0105] In one embodiment of the present application, the ciphertext password includes a second ciphertext password, and the second ciphertext password is the database connection password of the encrypted database connection tool. When the processor executes the computer program, the following steps are further implemented: Read the encryption algorithm used by the database connection tool and the second encryption key corresponding to the encryption algorithm from the target information, and use the encryption algorithm and the second encryption key as the decryption information.
[0106] In one embodiment of the present application, when the processor executes the computer program, the following steps are further implemented: Collect the target information from the target server based on the obtained command execution permission of the target server; Wherein, the command execution permission is obtained after a penetration attack on the target server.
[0107] The computer device provided by the embodiments of the present application has the same implementation principle and technical effects as the above method embodiments, and will not be described in detail here.
[0108] In one embodiment of the present application, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented: Collect the target information from the target server; Obtain the database connection password of the database project in the target server and the database connection password of the database connection tool based on the target information, where the database connection password includes a plaintext password and a ciphertext password; Obtain the decryption information based on the target information, and decrypt the ciphertext password based on the decryption information to obtain the decrypted password; Generate a penetration network topology diagram based on the decrypted password, the plaintext password, and the target information.
[0109] In one embodiment of the present application, when the computer program is executed by a processor, the following steps are further implemented: obtaining first configuration file information of a database project and second configuration file information of a database connection tool based on target information; obtaining the path of the project folder where the database project is deployed based on the first configuration file information, and traversing the project folder based on the path to obtain the database password configuration file of the database project from the project folder, and reading the database connection password of the database project from the database password configuration file; reading the database connection password of the database connection tool from the second configuration file information.
[0110] In one embodiment of the present application, the target information includes registry information and service list information. When the computer program is executed by a processor, the following steps are further implemented: obtaining a software list of the software installed in the target server based on the registry information and the service list information; determining the database project and the database connection tool in the target server according to the software list.
[0111] In one embodiment of the present application, the ciphertext password includes a first ciphertext password, and the first ciphertext password is the encrypted database connection password of the database project. When the computer program is executed by a processor, the following steps are further implemented: determining the encryption method of the first ciphertext password; obtaining decryption information based on the target information according to the encryption method.
[0112] In one embodiment of the present application, when the computer program is executed by a processor, the following steps are further implemented: if the encryption method is the windows DPAPI encryption method, obtaining the system user password and the system master key based on the target information, and using the obtained system user password and system master key as the decryption information; if the encryption method is the local encryption method, obtaining the encrypted code file of the database project and the first encryption key corresponding to the encrypted code file based on the target information, and using the obtained encrypted code file and the first encryption key as the decryption information.
[0113] In one embodiment of the present application, when the computer program is executed by a processor, the following steps are further implemented: obtaining the system user password from the target information; obtaining the system master key from the target server based on the system user password.
[0114] In one embodiment of the present application, the target information includes the first configuration file information of the database project. When the computer program is executed by a processor, the following steps are further implemented: obtaining the path of the project folder where the database project is deployed based on the first configuration file information; traversing the project folder based on the path to obtain the encrypted code file and the first encryption key from the project folder.
[0115] In one embodiment of the present application, the ciphertext password includes a second ciphertext password, which is the encrypted database connection password of the database connection tool. When the computer program is executed by a processor, the following steps are further implemented: reading the encryption algorithm used by the database connection tool and the second encryption key corresponding to the encryption algorithm from the target information, and using the encryption algorithm and the second encryption key as decryption information.
[0116] In one embodiment of the present application, when the computer program is executed by a processor, the following steps are further implemented: collecting target information from the target server based on the obtained command execution permission of the target server; wherein, the command execution permission is obtained after a penetration attack on the target server.
[0117] The computer-readable storage medium provided in this embodiment has the same implementation principle and technical effects as the above method embodiment, and will not be elaborated here.
[0118] In one embodiment of the present application, a computer program product is provided, including a computer program. When the computer program is executed by a processor, the following steps are implemented: collecting target information from the target server; obtaining the database connection password of the database project and the database connection password of the database connection tool in the target server based on the target information, wherein the database connection password includes a plaintext password and a ciphertext password; obtaining decryption information based on the target information, and decrypting the ciphertext password based on the decryption information to obtain a decrypted password; generating a penetration network topology diagram based on the decrypted password, the plaintext password, and the target information.
[0119] In one embodiment of the present application, when the computer program is executed by a processor, the following steps are further implemented: obtaining the first configuration file information of the database project and the second configuration file information of the database connection tool based on the target information; obtaining the path of the project folder where the database project is deployed based on the first configuration file information, and traversing the project folder based on the path to obtain the database password configuration file of the database project, and reading the database connection password of the database project from the database password configuration file; reading the database connection password of the database connection tool from the second configuration file information.
[0120] In one embodiment of the present application, the target information includes registry information and service list information. When the computer program is executed by a processor, the following steps are further implemented: obtaining a software list of the software installed in the target server based on the registry information and the service list information; determining the database project and the database connection tool in the target server according to the software list.
[0121] In one embodiment of the present application, the ciphertext password includes a first ciphertext password, and the first ciphertext password is the database connection password of the encrypted database item. When the computer program is executed by a processor, the following steps are further implemented: determining the encryption method of the first ciphertext password; and obtaining decryption information based on the target information according to the encryption method.
[0122] In one embodiment of the present application, when the computer program is executed by a processor, the following steps are further implemented: if the encryption method is the windows DPAPI encryption method, obtaining the system user password and the system master key based on the target information, and using the obtained system user password and system master key as decryption information; if the encryption method is the local encryption method, obtaining the encrypted code file of the database item and the first encryption key corresponding to the encrypted code file based on the target information, and using the obtained encrypted code file and the first encryption key as decryption information.
[0123] In one embodiment of the present application, when the computer program is executed by a processor, the following steps are further implemented: obtaining the system user password from the target information; and obtaining the system master key from the target server based on the system user password.
[0124] In one embodiment of the present application, the target information includes the first configuration file information of the database item. When the computer program is executed by a processor, the following steps are further implemented: obtaining the path of the project folder where the database item is deployed based on the first configuration file information; and traversing the project folder based on the path to obtain the encrypted code file and the first encryption key from the project folder.
[0125] In one embodiment of the present application, the ciphertext password includes a second ciphertext password, and the second ciphertext password is the database connection password of the encrypted database connection tool. When the computer program is executed by a processor, the following steps are further implemented: reading the encryption algorithm used by the database connection tool and the second encryption key corresponding to the encryption algorithm from the target information, and using the encryption algorithm and the second encryption key as decryption information.
[0126] In one embodiment of the present application, when the computer program is executed by a processor, the following steps are further implemented: collecting target information from the target server based on the obtained command execution permission of the target server; wherein the command execution permission is obtained after a penetration attack on the target server.
[0127] The computer program product provided in this embodiment has the same implementation principle and technical effects as those in the above method embodiment, and will not be elaborated herein.
[0128] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memories. Non-volatile memory can include Read-Only Memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in the present application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in the present application can be general-purpose processors, central processors, graphics processors, digital signal processors, programmable logic devices, data processing logics based on quantum computing, etc., without limitation.
[0129] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this specification.
[0130] The above-described embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.
Claims
1. A method for collecting penetration testing information, characterized in that, The method is executed by a unified scheduling server, and the method includes: Collect target information from a target server; wherein, the target information includes registry information and service list information; Based on the registry information and the service list information, obtain a software list of the software installed in the target server; Determine the database project and the database connection tool in the target server according to the software list; Based on the target information, obtain the database connection password of the database project in the target server and the database connection password of the database connection tool, wherein the database connection password includes a plaintext password and a ciphertext password; Based on the target information, obtain decryption information, and based on the decryption information, decrypt the ciphertext password to obtain a decrypted password; wherein, the decryption information includes an encryption method, a system master key, and an encryption code file; Generate a penetration network topology diagram based on the decrypted password, the plaintext password, and the target information; Wherein, the obtaining the database connection password of the database project in the target server and the database connection password of the database connection tool based on the target information includes: Based on the target information, obtain the first configuration file information of the database project and the second configuration file information of the database connection tool; Based on the first configuration file information, obtain the path of the project folder where the database project is deployed, and based on the path, traverse the project folder to obtain the database password configuration file of the database project from the project folder, and read the database connection password of the database project from the database password configuration file; Read the database connection password of the database connection tool from the second configuration file information.
2. The method according to claim 1, characterized in that, The ciphertext password includes a first ciphertext password, and the first ciphertext password is the encrypted database connection password of the database project. The obtaining the decryption information based on the target information includes: Determine the encryption method of the first ciphertext password; According to the encryption method, obtain the decryption information based on the target information.
3. The method according to claim 2, characterized in that, The obtaining the decryption information based on the target information according to the encryption method includes: If the encryption method is the windowsDPAPI encryption method, obtain the system user password and the system master key based on the target information, and use the obtained system user password and the system master key as the decryption information; If the encryption method is the local encryption method, obtain the encryption code file of the database project and the first encryption key corresponding to the encryption code file based on the target information, and use the obtained encryption code file and the first encryption key as the decryption information.
4. The method according to claim 3, characterized in that, The obtaining the system user password and the system master key based on the target information includes: Obtain the system user password from the target information; Based on the system user password, obtain the system master key from the target server.
5. The method according to claim 3, characterized in that, The target information includes the first configuration file information of the database project. Obtaining the encrypted code file of the database project and the first encryption key corresponding to the encrypted code file based on the target information includes: Obtaining the path of the project folder where the database project is deployed based on the first configuration file information; Based on the path, traversing the project folder to obtain the encrypted code file and the first encryption key from the project folder.
6. The method according to claim 1, characterized in that, The ciphertext password includes a second ciphertext password, which is the database connection password of the encrypted database connection tool. Obtaining decryption information based on the target information includes: Reading the encryption algorithm used by the database connection tool and the second encryption key corresponding to the encryption algorithm from the target information, and using the encryption algorithm and the second encryption key as the decryption information.
7. The method according to claim 1, characterized in that, Collecting the target information from the target server includes: Collecting the target information from the target server based on the obtained command execution permission of the target server, where the command execution permission is obtained after a penetration attack on the target server.
8. A device for collecting penetration testing information, characterized in that, The device is configured in a unified scheduling server, and the device includes: A collection device for collecting target information from a target server; where the target information includes registry information and service list information; A first acquisition module for obtaining the database connection password of the database project in the target server and the database connection password of the database connection tool based on the target information, where the database connection password includes a plaintext password and a ciphertext password; A decryption module for obtaining decryption information based on the target information and decrypting the ciphertext password based on the decryption information to obtain a decrypted password; where the decryption information includes an encryption method, a system master key, and an encrypted code file; A generation module for generating a penetration network topology diagram based on the decrypted password, the plaintext password, and the target information; Among them, the first acquisition module is specifically used to obtain the first configuration file information of the database project and the second configuration file information of the database connection tool based on the target information; obtaining the path of the project folder where the database project is deployed based on the first configuration file information, and based on the path, traversing the project folder to obtain the database password configuration file of the database project from the project folder, and reading the database connection password of the database project from the database password configuration file; reading the database connection password of the database connection tool from the second configuration file information; The device further includes a second acquisition module and a determination module; The second acquisition module is used to obtain a software list of the software installed in the target server based on the registry information and the service list information; The determination module is used to determine the database project and the database connection tool in the target server according to the software list.
9. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 7.
10. A computer-readable storage medium, having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 7.
11. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Database detection method and device, storage medium and electronic device
CN112818352A